Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What do security teams get wrong about improving…
Governance, Ownership & Risk

What do security teams get wrong about improving productivity and security at the same time?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

A common mistake is assuming stronger security must always slow people down. In practice, poor design slows users, while well-governed access can improve both control and efficiency. Teams often overfocus on policy restrictions instead of workflow design, where better defaults, automated provisioning, and clearer access paths reduce friction and lower the chance of risky workarounds.

Why This Matters for Security Teams

The productivity-versus-security debate usually starts in the wrong place. Security teams often try to preserve efficiency by adding exceptions, shared access, or broad permissions, then call the result a compromise. That approach tends to hide risk rather than remove friction. The better lens is workflow design: when access is predictable, scoped, and easy to request, people move faster and make fewer mistakes. NHI Management Group’s Ultimate Guide to NHIs notes that 97% of NHIs carry excessive privileges, which is exactly the kind of hidden permission sprawl that slows operations later.

This matters because productivity losses often show up as shadow work, not formal tickets. Users route around controls when access is unclear, approvals are slow, or secrets are hard to retrieve safely. That creates more support load, more ad hoc access, and more exposure. Current guidance from the NIST Cybersecurity Framework 2.0 emphasises integrated risk management, which fits this problem better than a simple restrict-and-review model. In practice, many security teams encounter control failures only after users have already built unofficial shortcuts to get work done.

How It Works in Practice

Improving both productivity and security usually means replacing manual gatekeeping with safer defaults. That starts by mapping the actual workflow: who needs access, what they need to do, which systems they touch, and how long that access should last. Instead of pushing users into permanent permissions, teams can use just-in-time access, short-lived credentials, and automated approval paths that are tied to task context. This reduces waiting time while narrowing the window of exposure.

For NHIs, the same principle applies even more strongly. Machine identities should not rely on static, long-lived secrets embedded in code or passed around informally. The NIST framework is useful here because it frames security as a lifecycle problem rather than a one-time control decision. NHIMG research shows that 96% of organisations store secrets outside secrets managers in vulnerable locations, and that kind of sprawl creates both operational friction and incident response pain. A well-governed secrets workflow gives engineers faster access without asking them to copy credentials by hand.

  • Use policy-based access so approvals happen at request time, not through permanent standing access.
  • Issue ephemeral credentials with clear expiry and automatic revocation when the task ends.
  • Separate high-risk actions from normal work, so users do not need elevated access for routine tasks.
  • Make the secure path the easiest path, including self-service requests, clear ownership, and automated rotation.

Security teams should also measure process friction directly. Ticket aging, failed access requests, secret retrieval time, and emergency privilege grants often reveal where controls are slowing work more than they are reducing risk. These controls tend to break down in environments with heavy cross-team dependencies and legacy systems that cannot support short-lived access or automated rotation.

Common Variations and Edge Cases

Tighter control often increases short-term engineering overhead, requiring organisations to balance stronger governance against delivery speed. That tradeoff is real, especially during migration from legacy IAM, but it should be temporary rather than permanent. Best practice is evolving toward controls that are secure by default and low-friction in normal use, rather than systems that rely on users to remember policy.

Some environments need special handling. Shared service accounts, regulated production systems, and third-party integrations may not tolerate fast-moving permission models without careful transition planning. In those cases, the goal is not to eliminate all standing access overnight, but to reduce its scope, document the exception, and put compensating controls around it. The State of Non-Human Identity Security shows why this matters: lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, so convenience that depends on static access is usually expensive later.

There is no universal standard for this yet, especially where identity, secrets, and workflow tooling are fragmented. The practical target is not “more controls” but fewer unnecessary decisions for users and fewer standing privileges for systems. Done well, productivity improves because people spend less time asking for access and less time working around it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Least privilege and access control directly address friction from broad permissions.
OWASP Non-Human Identity Top 10NHI-03Credential rotation is central when static secrets create both risk and workflow drag.
NIST AI RMFGovernance and measurement support secure workflows that do not slow delivery.
CSA MAESTROGOV-01Agent and workload governance helps align access, automation, and safety.
OWASP Agentic AI Top 10A1Dynamic access patterns require runtime controls for autonomous systems.

Reduce standing access and automate task-based approvals so users get only the access they need.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org